No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Cloud Firewall (formerly CloudGuard Network Security) vs Sangfor NGAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 15, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
591
Ranking in other categories
Secure Web Gateways (SWG) (2nd), Intrusion Detection and Prevention Software (IDPS) (1st), Software Defined WAN (SD-WAN) Solutions (1st), WAN Edge (1st), ZTNA (1st), Unified Threat Management (UTM) (1st)
Check Point Cloud Firewall ...
Ranking in Firewalls
8th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
167
Ranking in other categories
Managed Security Services Providers (MSSP) (1st), Software Defined WAN (SD-WAN) Solutions (5th), Cloud and Data Center Security (6th), WAN Edge (3rd), Unified Threat Management (UTM) (4th)
Sangfor NGAF
Ranking in Firewalls
22nd
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Firewalls category, the mindshare of Fortinet FortiGate is 16.0%, down from 21.6% compared to the previous year. The mindshare of Check Point Cloud Firewall (formerly CloudGuard Network Security) is 2.1%, up from 0.4% compared to the previous year. The mindshare of Sangfor NGAF is 1.1%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls Mindshare Distribution
ProductMindshare (%)
Fortinet FortiGate16.0%
Check Point Cloud Firewall (formerly CloudGuard Network Security)2.1%
Sangfor NGAF1.1%
Other80.8%
Firewalls
 

Featured Reviews

Abhinandan Yadav - PeerSpot reviewer
Network Security Engineer at a consultancy with 51-200 employees
Unified security and sd-wan have improved uptime and cut wan costs for multi-site branches
Users report stability issues in certain versions, which requires regular updates. Real-world attacks have also highlighted the need for urgent patching of vulnerabilities.Fortinet FortiGate, while a powerful and feature-rich web firewall, could improve in areas like firmware stability, documentation, and ease of use. The learning curve can be steep for some users. For beginners, support quality can vary, and frequent updates with occasional vulnerabilities call for careful patch management. However, once Fortinet FortiGate is configured, it remains highly reliable and efficient. Customer support needs improvement, as I find it very slow, with reports from other users reflecting that customer support is inadequate.
Viral Shaa - PeerSpot reviewer
IT Security Analyst at Eos Energy Enterprises, Inc.
Cloud security has unified hybrid policies and now protects critical energy workloads continuously
I would say Check Point Cloud Firewall (formerly CloudGuard Network Security) is valuable due to its hybrid cloud security features. It offers granular policy management across the on-premises and cloud environments, giving administrators consistent control for configuration drift. We need to change the policy and the inbound and outbound traffic settings, indicating what traffic must be blocked or allowed, and this capability with Check Point provides significant input into our security strategy. Check Point Cloud Firewall (formerly CloudGuard Network Security) provides unified security management across both hybrid clouds and on-premises environments. Unified security management affects my security operations positively, as we maintain critical systems on the cloud that require strong security and air gap networks. This cloud-native routing and policy installation helps close gaps in protecting critical applications and environments from exposure to the public cloud. From an administrator's perspective, Check Point Cloud Firewall (formerly CloudGuard Network Security) enhances our organization with clearer and more intuitive logging, making decisions easier to understand without deep investigation. In the CloudGuard UI, I can see which threats have triggered alerts, and this information is available on the unified dashboard that provides details of the threat analysis upon alert. As a small team, we log into the console to check specific alerts for high or low network usage or machine shutdowns. If needed, I tune the configuration policy, and the visualizing tools with reporting functionality simplify tracking changes made on the firewall, including the relevant source IP or device names. We ingest logs into our SIEM for detailed oversight, which allows us to monitor any administrative changes. Check Point Cloud Firewall (formerly CloudGuard Network Security) has significantly reduced our organizational risk. We clearly understand our threat landscape and the associated risks. Onboarding the CloudGuard solution directly into our cloud environment has significantly lowered the risks throughout the network and it is easy to launch. When we assess our security posture with third-party assessments, we gain granular visibility into our network pre- and post-CloudGuard installation, showing how we have addressed significant risks and secured vulnerabilities.
Zaid Farooqui - PeerSpot reviewer
CIO at Indus Motor Company
Enhanced threat detection with integrated security features and good support
We are using application firewalling, WAF, and SD-WAN. The capabilities are mostly within the box. For example, you will get web application firewall WAF as part and parcel of this. SD-WAN is also bundled. It integrates with their SIEM and SOAR solutions very nicely. Lastly, the pricing point is very cost-efficient as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The installation was super easy, we were up and running in less than 50 minutes."
"The most valuable feature of Fortinet FortiGate is security, as they are known for efficiency and are on the top of Gartner Quadrant reviews, with an easy-to-use platform, a good graphical interface, simple configuration, and an overall good layer of security."
"Since deploying FortiGate 3401E clusters, we have observed: Dramatic Reduction in Risk Exposure—blocked peer-to-peer and unauthorized applications (e.g., BitTorrent) at the perimeter and east-west segments, eliminating a major source of malware and bandwidth abuse."
"FortiGate Next Generation Firewall has a very high ROI"
"FortiGate protects and secures our clients' networks. The security is solid, and it performs well. I think they use some artificial intelligence, so I think it's excellent equipment."
"We have used many other solutions, such as Check Point and Cisco Firepower, and I have found Fortinet FortiGate is much easier to configure."
"Routing and reporting are two areas where the product has an added advantage compared to any other product."
"The combined license for the network, the next-generation firewall, and the integration with SD-WAN for all branches are what I consider to be the best features. It's effective for multi-branch customers."
"The features of the solution which I have found most valuable are its flexibility and agility. It's a fully scalable solution, from our perspective. We can define scaling groups and, based on the load, it will create new instances. It's truly a product which is oriented toward the cloud mindset, cloud agility, and this is a great feature."
"Advanced check prevention is a great feature that provides threat intelligence at speed."
"Check Point Cloud Firewall (formerly CloudGuard Network Security) is easy to implement, easy to use, easy to install, and easy to configure, especially compared to other competitors such as Palo Alto, Fortinet, Sophos, and SonicWall."
"We consolidated from three management consoles and three clusters to only one, which is a big improvement."
"It makes securing our cloud workload super easy, and we are able to push any sort of policy changes we need pretty quickly"
"It's possible to sync the Check Point Management with the cloud portal, therefore allowing automated rules to be set in place whenever creating a new VM."
"It has improved the way our organization functions in terms of visualization, simplicity, manageability, and support."
"The most valuable feature is threat prevention."
"In our hospital, Sangfor NGAF works well for us in terms of ensuring confidentiality and availability, which are crucial in the healthcare industry."
"Sangfor has the best capabilities for securing connections, securing web browsers, securing servers, and general threat protection."
"You might try Sangfor if you are on a tight budget. The price is affordable, and Sangfor offers a lot of features. We don't have any complaints about Sangfor."
"Particularly good in the DPI where we can inspect inbound and outbound traffic."
"It is a stable solution."
"Sangfor NGAF specializes in ransomware detection and helps to protect our network from ransomware threats and malware."
"We are Sangfor Gold partners and I'd recommend this solution for the SMB market, as it is cost-effective and reliable."
"The level of support provided to local companies is good. They transform their application control and other settings according to that country."
 

Cons

"Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production."
"I would rate Fortinet support a six out of ten. The immediate response is not that good, particularly when raising a critical or P1 ticket; they lag in the immediate response."
"The support from Fortinet FortiGate could improve. They are not easily accessible when we need them."
"Its filtering is sometimes too precise or strict. We sometimes have to bypass and authorize some of the sites, but they get blocked. We know that they are trusted sites, but they are blocked, and we don't know why."
"We were not able to build a full-mesh VPN; however, I am not sure if this was the fault of Fortinet FortiGate."
"The reports are very basic."
"Need to Improvement in Reporting"
"The renewal price and the availability could be improved."
"The core security features of Check Point CloudGuard Network Security work really well, but a few usability areas hold it back: the policy propagation speed and parts of the interface."
"The only pain points we have had with it were when we did major version upgrades. Rather than being able to do incremental upgrades on those, we had to completely redeploy. I know that has changed recently, but we had some hiccups when we did the upgrades. This is the only issue we have had."
"There is room for improvement in how it handles deployment itself, but I am not sure. It could be due to Azure's limitations, not Check Point's."
"We are at the place where we are looking at better integration with the management system. We use an MDS today, and it is self-deployed. We want to get to the Smart-1 Cloud, but we do not know what that looks like today because it does not support a multi-domain setup. Smart-1 should either be able to do multi-domain or there should be some form of taking a multi-domain environment and putting it in Smart-1."
"It's meeting our needs at this time. If I could make it better, it would be by making it more standalone. That would be beneficial to us. I say that because our current platform for virtualization is VMware. The issue isn't any fault of Check Point, it's more how the virtualization platform partners allow for that partnership and integration. There has to be close ties and partnerships between the vendors to ensure interoperability and sup-portability. There is only so far that Check Point, or any security vendor technology can go without the partnership and enablement of the virtualization platform vendor as it relies on "Service Insertion" to maintain optimal performance."
"Greater automation would reduce the need for manual configuration and management."
"Areas for improvement include other Security Features like AntiVirus, AntiSpam, DLP etc."
"I haven't used CloudGuard Network Security in the past couple of years as I moved out of the network security role. However, based on my previous experience, there were improvements, especially in in-place upgrades. Regarding cost, it might be potentially cheaper considering resource utilization in Azure and VM costs, but licensing could be improved, possibly moving towards a simpler model."
"I would be happy if Sangfor developed a firewall designed specifically for home use, as well as for small businesses such as clinics and so on. A household version of the Sangfor firewall for your personal computer or laptop would be ideal, in my opinion."
"An area of improvement for Sangfor NGAF could be in the field of reporting and logging."
"Sangfor could improve by providing better real-time reporting, as the current reports don't offer the level of detail we need, especially for runtime insights."
"The tool is expensive."
"The support offered by the product has certain shortcomings where improvements are required. The knowledge levels and response time of the support team need improvement."
"However, the maintenance cost can be a bit high."
"Our experience with its customer support was quite challenging."
"They need to improve their research team and they need to study their data to analyze it and build the product."
 

Pricing and Cost Advice

"The solution is very expensive so pricing is rated a one out of ten."
"The solution is cheap."
"It is not a very costly product if you compare it with other products. The return on investment is also good. If you compare the return of investment and money that you are spending on this product with Palo Alto, Cisco, Check Point, and other solutions, the investment is very less. We are happy with this solution. The optional licenses are there, and you can choose which one you want and which one to avoid."
"The price of Fortinet FortiGate is the lowest in the market."
"The product is expensive. I rate its pricing a six out of ten."
"It cost us around $73,000 for three years."
"The price is relatively expensive compared to other solutions which are providing similar features."
"Fortinet FortiGate SWG is an affordable solution."
"It is fair. Its license covers all the features. There is a cost-benefit. The licensing for the cloud is better than on-premises because, with on-premises, you have to pay separately for different things."
"The product is too expensive."
"It is an expensive product, but when you realize that you need it, it does not feel so expensive. We have had a good experience with them as partners. They have helped us with designing and having good architecture and the best equipment at the best prices. We find it a good deal."
"It is not expensive, but it is a little bit above the middle range. There are other solutions that are a little more expensive than this, but they also have some interesting features."
"It is fairly priced, but it can be a little expensive from time to time."
"As a partner and solution provider for the last fifteen years, I have distanced myself from specific numbers. However, customer trust in the product is evident due to its comprehensive protective capabilities."
"Although I am not in sales and cannot comment extensively on pricing, it is known that Check Point’s licensing can be complex. However, it is a similar experience to other gateways and not particularly unique for cloud protection."
"Check Point CloudGuard Network Security's pricing is far better than Palo Alto's because Palo Alto is very expensive."
"It is one of the cheapest tools in the market."
"When it comes to the price of firewall solutions, Sangfor NGAF takes the cake."
"Sangfor NGAF is a cheaply priced product, especially if I consider the previous product that was used in my company."
"The price falls in the mid-range, neither exceptionally low nor high."
"In my opinion, the price of the tool is good in the Pakistani market. We can easily get discounts if needed."
"For four to five physical appliances for a licensed firewall, it costs approximately $4,000."
"The pricing is reasonable."
"We purchased one year technical support and return to factory support, and we also purchased one-year technical support services. So those were additional."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
896,510 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
10%
Manufacturing Company
9%
Financial Services Firm
7%
Outsourcing Company
10%
Computer Software Company
9%
Financial Services Firm
9%
Manufacturing Company
7%
Manufacturing Company
11%
Comms Service Provider
10%
Financial Services Firm
10%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business368
Midsize Enterprise135
Large Enterprise193
By reviewers
Company SizeCount
Small Business71
Midsize Enterprise41
Large Enterprise79
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise10
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
What is your experience regarding pricing and costs for Check Point CloudGuard Network Security?
We have encountered a few subscription-based licensing models for the virtual gateway and security enablement. We hav...
What needs improvement with Check Point CloudGuard Network Security?
I find troubleshooting a bit challenging with Check Point Cloud Firewall (formerly CloudGuard Network Security); one ...
What is your primary use case for Check Point CloudGuard Network Security?
My usual use cases for Check Point Cloud Firewall (formerly CloudGuard Network Security) involve onboarding as an ene...
What is your experience regarding pricing and costs for Sangfor NGAF?
The licensing cost is quite high compared to other available firewalls in the market.
What needs improvement with Sangfor NGAF?
The cost of licensing is very high compared to other firewalls available here. There should be improvements in hardwa...
What is your primary use case for Sangfor NGAF?
We are hosting applications over the platform, including websites and NAT traffic from our side. Because it's deploye...
 

Also Known As

Fortinet FortiGate Next-Generation Firewall
CloudGuard IaaS, Check Point vSEC, CloudGuard IaaS, Check Point Virtual Systems, Check Point CloudGuard Network Security
Sangfor NGAF Firewall Platform
 

Overview

 

Sample Customers

Amazon Web Services, Microsoft, IBM, Cisco, Dell, HP, Oracle, Verizon, AT&T, T-Mobile, Sprint, Vodafone, Orange, BT Group, Telstra, Deutsche Telekom, Comcast, Time Warner Cable, CenturyLink, NTT Communications, Tata Communications, SoftBank, China Mobile, Singtel, Telus, Rogers Communications, Bell Canada, Telkom Indonesia, Telkom South Africa, Telmex, Telia Company, Telkom Kenya
Physicians Choice Laboratory Services, Helvetica Insurance
The Ministry of Science, Technology, and Innovation (Indonesia), Lawson, Inc. (Philippines), Universiti Sultan Zainal Abidin (Indonesia), TEK Automotive (Italy), etc.
Find out what your peers are saying about Check Point Cloud Firewall (formerly CloudGuard Network Security) vs. Sangfor NGAF and other solutions. Updated: April 2026.
896,510 professionals have used our research since 2012.